Soru

Zorluk: KolayNetwork Security Monitoring and Alerting

A Security Operations Center (SOC) analyst receives an automated alert from a network intrusion detection system (NIDS) flagging potential command-and-control (C2) beaconing activity from an internal workstation. Place the following incident triage and response steps in the correct chronological order from first to last.

  1. 1Inspect raw packet captures and flow logs to validate that the alert is a true positive.
  2. 2Isolate the compromised workstation from the local network to sever the active C2 session.
  3. 3Deploy custom block rules on perimeter firewalls using the newly identified malicious IP address.
  4. 4Document the incident findings and update the network security monitoring baseline signatures.

Cevap

The correct sequence begins with validating the NIDS alert using raw packet captures and flow logs, followed by isolating the compromised workstation, deploying custom firewall block rules for the C2 IP, and concluding with incident documentation and updating network monitoring baselines.
The standard network security monitoring triage flow requires validating the security alert with raw telemetry first to confirm true positive status. Once validated, containment actions such as host isolation are performed immediately to block active command-and-control communication. Following containment, preventive controls like firewall block rules are updated across the network perimeter. Finally, the analyst completes post-incident procedures by documenting findings and updating monitoring baselines.

Adım Adım Çözüm

1
Validate the NIDS alert using raw network telemetry
Confirmed true positive C2 beaconing activity
Triage validation prevents taking intrusive containment measures on false alarms.
2
Isolate the host machine from the network
C2 communication severed and host network access contained
Immediate containment limits damage and prevents adversary lateral movement.
3
Apply firewall block rules based on extracted indicators
Perimeter network defenses updated with threat indicators
Prevents other internal hosts from communicating with the same external threat infrastructure.
4
Perform post-incident documentation and update detection rules
Network security monitoring baselines and detection logic refined
Ensures lessons learned are incorporated to prevent similar incidents and improve future response speed.

Anahtar Kavram

Incident triage and containment workflow for network security alerts
Bu soruyu puanla